
physmem2profit
Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

Recognizing the most likely APT groups responsible for an incident

A small utility to translate NTDS.dit files to SQLite format.

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Python implementation of the CaRT library for (un)inerting files.

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Lack of argument sanitization leading to password leakage in Ghostscript PDF versions up to 10.05.0.

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…


swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux…

Open source Android, iOS and Web app for learning about and managing digital and physical security. From how to send a secure message to dealing with…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Artifact collection tool for *nix systems